"The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns," Zscaler's ThreatLabz researchers wrote — and their data show exactly how targeted those campaigns have become.
Zscaler ThreatLabz: one campaign, 351 victims across 334 organizations
Over the course of a single month, Zscaler tracked a single ransomware campaign that hit 351 victims across 334 organizations. Those figures come from ThreatLabz telemetry and reporting summarized by the security firm. The campaign is notable not only for its scale but for the precision of its targeting: rather than a scattershot approach, attackers appear to have tailored their efforts to reach specific people inside affected firms.
Target profile: the 46-year-old manager in finance, sales, operations, HR, or marketing
The researchers report a striking demographic and role pattern among victims. Nearly two-thirds of the compromised accounts held manager-level titles or above. The average victim was a 46-year-old Gen Xer, and three-quarters of victims worked in accounting and finance, sales, operations, HR, or marketing. Roughly half of the affected accounts were tied to organizations in the industrial or IT sectors.
Those patterns suggest attackers are not aiming randomly at inboxes; they are choosing accounts whose day-to-day responsibilities touch invoices, payment approvals, budgets, supplier contracts, customer records, or HR files — the kinds of business processes that can influence a company’s decision to pay a ransom.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageBusiness privilege, not just technical privilege
Zscaler frames the shift as a move from seeking technical privileges (administrator rights) toward seeking what it calls "business privilege." "The value of a compromised managerial account lies in the breadth of business access associated with the position," ThreatLabz wrote. In practice, attackers combined information from compromised systems with publicly available data to map reporting lines and identify employees most likely to accelerate payment decisions.
The firm also found attackers frequently moved beyond a single foothold: more than a dozen organizations reported multiple employees compromised during the campaign. That lateral work through different business functions appears calculated to increase attackers' chances of reaching both valuable data and the people capable of influencing ransom outcomes.
Extortion and data theft: big year-over-year spikes
ThreatLabz situates the campaign inside a broader trend toward extortion and data theft. Zscaler said ransomware attempts blocked across its cloud platform increased 146 percent over the past year. At the same time, public extortion cases rose 70 percent and the volume of data stolen from victims climbed 92 percent. Those numbers underline the point the researchers make plainly: "The encryption is just the bit that victims notice."
What this means for security teams, middle managers, and IT/industrial organizations
- Security teams: The campaign's focus on managerial accounts and "business privilege" implies security teams will need to watch for compromises that confer access to business processes as well as technical admin rights, and to anticipate adversaries using public data to map reporting lines.
- Middle managers and business leaders (accounting, HR, sales, operations): Employees in these functions are disproportionately targeted; the research indicates attackers prize the authority and access inherent to those roles and may try to exploit established approval workflows.
- IT and industrial sector organizations: Roughly half of the affected accounts were in these sectors. Firms in those industries were therefore disproportionately represented among victims in this campaign and reported multiple compromises in some cases.
The campaign Zscaler describes reframes the visible part of ransomware — the encrypted files and the ransom note — as only the tip of a methodical effort to reach people who can move money, sign contracts, or unlock business processes. The data raise a pointed question for defenders: as attackers shift their attention from executives and administrators to the 40-something manager with access to invoices and contracts, how will organizations reassess which accounts are most critical to protect?




